The enterprise defines who is responsible for what in enterprise I&T and communicates it, covering levels of authority, responsibilities and accountability. Roles and responsibilities relating to I&T are set, agreed and communicated for all staff according to business needs, with a clear split of responsibility and accountability, particularly for decisions and approvals. Continuity needs, including backup staff and cross-training, are reflected in how roles are shaped. Current contact details and role descriptions are supplied to the service continuity process. Role descriptions oblige staff to observe the code of ethics, professional practice, and the procedures and policies set by management. Accountability is set through the roles. Roles are arranged so that no one role on its own can undermine a critical process. Supervision checks that roles are carried out properly, that each person has the authority and resources needed to perform them, and that performance is reviewed.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.